Technology

Coldcard's Source-Available License Left a $100M Entropy Bug Unguarded

Coldcard's firmware is source-available, not open source. The Commons Clause restricts commercial use, and the economic incentives that come with it. A five-year entropy flaw that cost users at least 1,596 BTC is the result.

5 min read
A hardware security device with a small screen and physical buttons sits on an open legal document covered in dense text, photographed under harsh overhead fluorescent light on a cluttered
Share

Coldcard firmware is not open source. The Commons Clause says so explicitly. A five-year entropy flaw says so in bitcoin.

Key takeaways

  • Coldcard firmware operates under MIT + Commons Clause licensing, which the Commons Clause's own FAQ states is explicitly "not Open Source", restricting the commercial rights that motivate serious third-party code review.
  • A seed-generation bug introduced in firmware v4.0.1 (March 2021) reduced effective entropy from 128 bits to roughly 40 bits on Mk2/Mk3 devices, sitting undetected for five years before attackers drained at least 1,596 BTC from approximately 7,300 addresses beginning July 30, 2026, per Galaxy Research data cited by CoinDesk.
  • Bitcoiners choosing self-custody tools need to treat the firmware license as a security variable: true FOSS (GPLv3, MIT without Commons Clause) creates the commercial incentive structure that pays for rigorous external review; source-available does not.

Attackers began sweeping bitcoin from Coldcard hardware wallets on July 30, 2026, exploiting a flaw in seed generation that had been sitting in the codebase since March 2021. Galaxy Research's high-confidence figures, reported by CoinDesk, put the damage at least 1,596 BTC drained from roughly 7,300 addresses, with other analytics estimates running higher. The largest single sweep pulled 1,082 BTC from 1,196 wallets in 41 minutes. Coinkite CEO Rodolfo Novak issued an immediate migration warning: "If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further."

The root cause: firmware v4.0.1 introduced a bug during a migration to Bitcoin Core's libsecp256k1 library. Seed generation silently fell back to MicroPython's software pseudorandom number generator rather than the device's dedicated hardware RNG. Two functions shared the same name; no build-time error fired. The result was effective entropy of roughly 40 bits on Mk2/Mk3 devices, against a 128-bit security target. That is a 2^88 reduction in the brute-force search space, roughly 300 septillion times easier to crack. Mk4, Mk5, and Q mixed in secure element entropy, reaching approximately 72 bits, still well below standard. Coinkite's official advisory details the affected firmware versions and the patched releases.

The flaw affected seeds generated from March 2021 through the patched firmware releases. Updating firmware does not fix an existing compromised seed. Users must generate a new seed on updated firmware and migrate funds on-chain. TFTC covered the initial disclosure here and the on-chain fallout here.

The License Is Not a Footnote

The timing deserves scrutiny. Coldcard's firmware was GPLv3-licensed as of mid-2020. On November 18, 2020, Coinkite switched to MIT + Commons Clause, removing the right to commercially sell software whose value derives substantially from the firmware. The entropy bug entered the codebase in firmware v4.0.0/v4.0.1, released March 2021, four months later.

Foundation Devices CEO Zach Herbert documented this sequence in detail:

The Commons Clause's own FAQ at commonsclause.com states the answer plainly: "Is this 'Open Source'? No." The Coldcard firmware repository sits at github.com/Coldcard/firmware under the COPYING-CC license file. The code is publicly readable. It is not open source under the Open Source Initiative's definition or the Free Software Foundation's four freedoms.

That distinction has a concrete security consequence. GPL licensing gives competitors and commercial partners a direct economic reason to audit upstream code: they are building on it, they can build on it, and any vulnerability they find protects their own product. Coinkite's license switch in November 2020 cut that incentive off. The most motivated external reviewer Coldcard had at the time, Foundation Devices, was actively building on the GPLv3 codebase. That commercial pressure vanished with the license change. Four months later, the entropy bug shipped.

Coinkite acknowledged they used AI to review their own code before the attack. It missed the issue. Internal review, whether human or AI-assisted, does not replicate the adversarial scrutiny that comes from commercial third parties with skin in the game. The Linux kernel is the clearest counterexample: decades of external commercial review, funded by companies whose products depend on it, have produced one of the most hardened codebases in history. Source-available licenses produce a different incentive structure and, over time, different outcomes.

The falsifiable version of this thesis: if a postmortem shows the entropy bug predates the license change, existed in the GPLv3 era, or was independently reported and ignored before November 2020, the licensing-causes-undiscovery link breaks. None of that evidence has emerged as of publication. The burden of proof now sits with Coinkite's formal technical review, which has not been published. The broader point about FOSS incentives stands regardless: open source creates the possibility of verification; commercial rights are what make that verification economically rational.

What Affected Users Must Do Now

Migration is not optional for anyone who generated a seed on Mk2/Mk3 firmware v4.0.1 through v4.1.9, or on Mk4/Mk5/Q devices before the patched releases. The Coinkite security advisory details the exact affected version ranges and step-by-step migration guidance. Jonathan Goodman, a Toronto entrepreneur who lost 18.25 BTC, described the situation succinctly in his August 1 X post: "Perhaps the hardest part about this is that I did everything right." Doing everything right at the device level was not enough when the entropy was broken at the firmware level for five years.

For anyone evaluating self-custody hardware going forward: check the firmware license. A GitHub repository with public code is not the same as a FOSS license. The commercial rights embedded in true open source licenses are the economic mechanism that attracts the external reviewers whose incentives are aligned with finding problems before attackers do. Source-available is a weaker security model. This event is the proof of concept. Full on-chain forensics continue; TFTC's earlier coverage has additional detail on the attacker's movement of funds.

Sources

Frequently Asked Questions

Open source software, under the Open Source Initiative's definition, grants users the right to run, study, modify, and distribute the software commercially without restriction. Source-available software makes code publicly readable but restricts one or more of those rights. Coldcard's MIT + Commons Clause license prohibits commercial redistribution, which disqualifies it from both the OSI's Open Source Definition and the FSF's Free Software Definition. The Commons Clause FAQ states this directly.

No. Coldcard firmware is hosted publicly on GitHub but licensed under MIT + Commons Clause. The Commons Clause restricts the right to sell software whose value derives substantially from the licensed code. Per the Commons Clause's own documentation, software under this license does not qualify as Open Source. Coinkite's version history confirms the switch from GPLv3 to MIT + Commons Clause occurred on November 18, 2020.

If a seed was generated on Mk2/Mk3 firmware v4.0.1 through v4.1.9, or on Mk4/Mk5/Q devices before the patched firmware versions (Mk3: v4.2.0+; Mk4/Mk5: v5.6.0+; Q: v1.5.0Q+), yes. Updating firmware alone does not repair an already-generated seed. A new seed must be generated on patched firmware and funds migrated on-chain to a new address. Full guidance is in the Coinkite security advisory.

News and analysis, not financial, investment, legal, or tax advice. Figures and quotes are verified against primary sources where possible. See our editorial and financial disclosures.

Keep reading

All of TFTC

The Bitcoin Brief

Bitcoin, markets, energy, and the tech reshaping all three.

A daily brief on the freedom tech building a parallel economy, written for the curious and the convicted alike. Signal, not noise. Truth for the Commoner.

Free, daily. Unsubscribe anytime.